It is important for us to process and use your data only in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (collectively the “Data Protection Laws”) and your expectations, and to be transparent with you in how we process and use your data.
Metsec is the UK’s largest specialist cold roll-forming company providing products for the construction and manufacturing industries. Established for over 80 years, Metsec is owned by the voestalpine group, one of Europe’s leading specialist engineering companies. We are part of voestalpine Metal Forming division, the world’s leading provider of high-quality metal processing solutions with production facilities all around the globe.
In connection with the different ways we may interact with you and the various services that we provide, we collect the following categories of data:
C1: Contact information, including name, address, telephone number and e-mail address, and payment data such as credit card numbers.
C2: Communication data between you and us, including recordings of calls to our service centres, e-mail communication, online chats, comments and reviews collected through surveys or posted on our channels and on social media platforms.
C3: Digital information data collected when you visit our websites, applications or other digital platforms, including IP-addresses, browser data, traffic data, social media behaviour, and user patterns. If you subscribe to our newsletters, we may collect data regarding which newsletters you open, your location when opening them and whether you access any links inserted in the newsletters.
If the personal data is not provided or is insufficient or if Metsec cannot collect the respective personal data, the purposes described may not be met or the received inquiry could not be processed. Note that this would not be considered failure to fulfill our obligations under a contract.
Most of the data that we have about you are provided by you. We collect C3 data from our websites, applications and similar digital platforms. Data may be collected from publicly available sources, information databases and credit agencies.
Description: We use C1 and C2 data to ensure that we can supply the goods or services you have requested. We may provide such information by electronic or other means.
Legal basis: We use such data as part of our business relationship. Further, we use such data to provide you with other information necessary to fulfil our legitimate interests, including to ensure that we process invoices and to contact you, where necessary, concerning any orders you may place with voestalpine Metsec, process payments, for accounting, billing and collection purposes, to make deliveries, to settle disputes, enforcing our contractual agreements and establishing, exercising or defending legal claims. Also, processing is necessary for the performance of the contract to which the data subject is party, or for pre-contractual measures. For, ensuring compliance with legal obligations (such as record keeping obligation in accordance with tax and commercial law) and Metsec policies.
Disclosure: We may disclose C1 data to our corporate partners, as they may need this information to communicate with you and to provide support and assistance.
Description: We use C1 and C3 data to provide you with newsletters from us about our products and services.
Legal basis: Our use of such data is based on our legitimate interests in providing you with relevant information to promote our products and services. You may at any time opt out of receiving such information.
Disclosure: We may process your data to enable us to send you relevant information to promote our products services.
Description: We may use and compile C1, C2, and C3 data for profiling purposes. Profiling is an automated processing of personal data where your personal data is used to evaluate, analyse and predict your preferences, interests and behaviour (profiling). We use this data to provide you with customised information about services and offers that you may appreciate.
Legal basis: We carry out profiling to fulfil a legitimate interest, which is to customise our services for your benefit. You may at any time object to our use of your personal data for profiling purposes.
Disclosure: We will not disclose the profiles we have generated based on your data to third parties other than any member of our group.
Description: We may carry out video surveillance on premises and store C3 data to prevent crime and ensure your safety.
Legal basis: We carry out video surveillance that is necessary to fulfil a legitimate interest which is to prevent crime and ensure your safety while you are on our premises.
Disclosure: We will not disclose video surveillance footage to third parties unless required by law or on request from authorities.
We will only store your data for as long as it is necessary to fulfil the purpose of the processing of your data.
We will store your C1, C2, C3, data from the point for the duration of our contractual relationship and up to a period of 6 months after our contractual relationship has ended, if we believe this is necessary to handle potential complaints or claims. We may store your data longer if you wish for us to keep your data and you have consented to this.
We will store C3 data as required by applicable law.
We will store your C1, C2, C3 data for as long as you wish to receive information and marketing communications from us.
We store video surveillance footage for a period of 1 month. If we deem it necessary to deliver video surveillance footage to the police due to a criminal incident or similar, we may store the video surveillance footage for 3 months.
voestalpine Metsec plc provides services worldwide. We have affiliates, branch offices, agents and corporate partners that are established in these jurisdictions outside of the European Economic Area to which we may transfer data, as described in section 5 above. We will ensure that your data is adequately protected by the receiving parties in such countries. Adequate protection may typically be to impose on the receiving party contractual obligations that ensure that it maintains the same level of privacy and data security as practised by us. You may ask for further information or a copy of the safeguards that we have in place to ensure lawful transfer of your data.
Where you have provided us with your details for marketing purposes, we may also allow other companies in our group, to contact you occasionally about related products and services which may be of interest to you, where you have given consent to do so. They may contact you by post and telephone, as well as by email. If you change your mind about being contacted by these companies in the future, please let us know.
If we pass your information to non-EEA/International organisations for processing on our behalf, we will ensure the appropriate level of protection is offered to your information, to ensure its protection as per the Data Protection Laws, while taking into account that the non-EEA country may not have equivalent data protection and privacy laws to the EEA.
Finally, if our business or part of it enters into a joint venture with or is sold to or merged with another business entity, your information may be disclosed to our new business partners or owners.
Unless required to do so by law, we will not otherwise share, sell or distribute any of the information you provide to us without your consent.
We take appropriate measures to ensure that any personal data is kept secure, including security measures to prevent personal data from being accidentally lost, or used or accessed in an unauthorised way. We limit access to your personal data to those who have a genuine business need to know it. Those processing your information will do so only in an authorised manner and are subject to a duty of confidentiality.
Under the GDPR and the Data Protection Act 2018, you have a number of important rights. In summary, those include rights to:
For further information on each of those rights, including the circumstances in which they apply, see the guidance from the UK Information Commissioner’s Office (www.ico.org.uk) on individual’s rights under the GDPR and the Data Protection Act 2018.
If you would like to exercise any of those rights, please contact us via the details below. We will ask you to provide us with confirmation of your identity, for example, by sending us an electronic copy of your ID.
If you wish to make a complaint about how your personal data is being processed by Metsec (or third parties), or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority (ICO) and Metsec Information Security Team. Please see the relevant contact details below.
voestalpine Metsec plc, Broadwell Road, Oldbury, West Midlands, B69 4HF.
Tel: +44 (0) 121 601 6000
Supervisory authority contact details:
The Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF.
Tel: +44 (0) 303 123 1113